CVE-2013-3958: Siemens SIMATIC PCS7

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.

Affected products

  • Siemens SIMATIC PCS7: up to and including 8.0; version 8.0 only
  • Siemens Wincc: up to and including 7.2; version 7.0 only; version 7.1 only

Published 2013-06-14. Last modified 2026-06-16.